Re: [fw-wiz] GIDS, Intrusion Prevention: A Firewall by Any Other Name

From: Marcus J. Ranum (mjr@ranum.com)
Date: 08/12/02


To: Ryan Russell <ryan@securityfocus.com>, Crispin Cowan <crispin@wirex.com>
From: "Marcus J. Ranum" <mjr@ranum.com>
Date: Mon Aug 12 20:10:04 2002

Ryan Russell wrote:
>I think a more interesting question is: if GIDS is the new "firewall",
>then why did firewalls running on top end PCs max at 100mbps or so with
>just a few dozen rules and terribly simply filtering capabilities...

Because they're really really really badly written.

There may be other reasons but "crappy code" is #1.

mjr.

---
Marcus J. Ranum				http://www.ranum.com
Computer and Communications Security	mjr@ranum.com


Relevant Pages

  • Re: [fw-wiz] GIDS, Intrusion Prevention: A Firewall by Any Other Name
    ... > then why did firewalls running on top end PCs max at 100mbps or so with ... > just a few dozen rules and terribly simply filtering capabilities... ... Did PCs just get that much faster? ...
    (Firewall-Wizards)
  • Re: Suspicious E-Mail Arriving at Private Server
    ... >>You've just invited another load of them by your newsgroup posting. ... >>They are from PCs infected with the Swen virus. ... emails to a queue for further filtering or direct to user mailboxes. ... FreeBSD is a future project (I was going to try Postfix but saw ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Need small office firewall rec ASAP
    ... > router/firewall of some type and upgrading all PCs to XP. ... > get a complete package that had anti-virus and content filtering in ... > of 10 PCs on the network though not all need to get to the outside. ... The smoothwall 1.0 GPL runs better on slower hardware than IPCop ...
    (comp.security.firewalls)
  • Re: Strange loopback traffic on intranet interface
    ... > to do NAT and some filtering between my cable router ... > and intranet PCs. ... > but on intranet le0 is still there. ... , but on bunch of addresses ...
    (comp.security.firewalls)
  • Re: Strange loopback traffic on intranet interface
    ... > to do NAT and some filtering between my cable router ... > and intranet PCs. ... > but on intranet le0 is still there. ... , but on bunch of addresses ...
    (comp.os.linux.networking)